Description
LogicalDOC Enterprise 7.7.4 contains multiple authenticated OS command execution vulnerabilities that allow attackers to manipulate binary paths when changing system settings. Attackers can exploit these vulnerabilities by modifying configuration parameters like antivirus.command, ocr.Tesseract.path, and other system paths to execute arbitrary system commands with elevated privileges.
Problem types
Product status
7.7.3
7.7.2
7.7.1
7.6.4
7.6.2
7.5.1
7.4.2
7.1.1
Credits
LiquidWorm as Gjoko Krstic of Zero Science Lab
References
www.exploit-db.com/exploits/44021
www.zeroscience.mk/en/vulnerabilities/ZSL-2018-5452.php
www.exploit-db.com/exploits/44021 (ExploitDB-44021)
www.logicaldoc.com (Official Product Homepage)
www.zeroscience.mk/en/vulnerabilities/ZSL-2018-5452.php (Zero Science Lab Disclosure (ZSL-2018-5452))
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.